Stolen Credentials Flood Dark Web, Enterprise Access Commands Premium Prices

The underground market for stolen credentials has reached unprecedented levels, with 2.86 billion compromised records circulating in 2025 alone. This surge has led to a significant devaluation of individual login data, while verified access to large enterprises now commands premium prices.

Massive Surge in Stolen Credentials

Infostealer malware has become a primary tool for cybercriminals, infiltrating systems through phishing attacks, fake software updates, and malicious downloads. Once inside, these programs extract browser passwords, cookies, and other sensitive data. The harvested information is then exploited to gain unauthorized access to cloud services, VPNs, and business accounts.

Analysts have observed a dramatic increase in the volume of stolen credentials. In 2025, 2.86 billion records were compromised, and the first half of the following year saw 1.8 billion credentials stolen—an 800% increase compared to the previous six months. This glut has rendered individual credentials nearly worthless, with Social Security numbers selling for as little as $1 to $6, and complete identity packages priced between $20 and $100.

Enterprise Access Becomes a Lucrative Commodity

While individual credentials have depreciated, access to large organizations has become highly valuable. Research indicates that the average price for initial access broker listings on underground forums skyrocketed from approximately $2,726 in 2024 to $113,275 in 2025—a staggering 4,055% increase. This surge is partly due to listings offering access to high-revenue targets, signaling a burgeoning market for premium enterprise access.

Healthcare records, which are difficult to replace, maintain a high value, typically selling for $250 to $310 each. Verified cryptocurrency accounts also fetch higher prices. For organizations in sectors like healthcare, finance, and critical infrastructure, this trend underscores the need to scrutinize internet-facing systems, privileged accounts, and internal movement detection mechanisms.

Session Cookies: A New Target for Bypassing MFA

Cybercriminals are increasingly targeting session cookies—small data files that keep users logged in after authentication. By stealing these cookies, attackers can replay approved sessions, effectively bypassing password prompts and multi-factor authentication (MFA) checks. This tactic highlights the necessity for authentication systems to protect sessions post-sign-in.

To mitigate this risk, organizations should implement shorter session lifetimes, bind sessions to specific devices when possible, and monitor for session replay attempts. Transitioning to phishing-resistant MFA and continuous verification methods can further reduce the value of stolen data to cybercriminals.

The commoditization of stolen credentials, coupled with the premium placed on enterprise access, reflects a shifting landscape in cybercrime. Organizations must adapt by enhancing their security measures, particularly around authentication and session management, to stay ahead of these evolving threats.